Skip to content

Conversation

@renovate
Copy link
Contributor

@renovate renovate bot commented Dec 2, 2025

This PR contains the following updates:

Package Change Age Confidence
org.springframework.security:spring-security-test (source) 6.5.7 -> 7.0.2 age confidence
org.springframework.security:spring-security-oauth2-jose (source) 6.5.7 -> 7.0.2 age confidence
org.springframework.security:spring-security-oauth2-client (source) 6.5.7 -> 7.0.2 age confidence
org.springframework.security:spring-security-core (source) 6.5.7 -> 7.0.2 age confidence

Release Notes

spring-projects/spring-security (org.springframework.security:spring-security-test)

v7.0.2

Compare Source

🪲 Bug Fixes

  • AuthorizationWebProxyConfiguration should only be active when both spring-security-web and spring-webmvc are on the classpath #​18315

v7.0.1

Compare Source

⭐ New Features

  • Stop deploying JavaDoc outside of Antora #​18200

🪲 Bug Fixes

  • An unexpected dependency appeared for spring-security-config of spring-security-web #​18307
  • Fix "typ" header value in NimbusJwtEncoder-encoded JWT #​18270
  • Fix broken link to Spring Boot docs #​18236
  • Fix documentation resource server sample title #​18231
  • Fix MyCustomDsl to use csrf(Customizer) instead of removed csrf().disabled() #​18223
  • Fix typo in AnnotationTemplateExpressionDefaults documentation #​18255
  • Fix typos in documentation depenendencies->dependencies #​18209
  • NimbusJwtEncoder produces JWT with wrong "typ" header value #​18269
  • OAuth2AuthorizationEndpointFilter should be applied after AuthorizationFilter #​18251
  • Remove requireProofKey warning for non-auth-code flows #​18221
  • Remove throws from MyCustomDsl in docs #​18224

🔨 Dependency Upgrades

  • Bump ch.qos.logback:logback-classic from 1.5.20 to 1.5.21 #​18214
  • Bump ch.qos.logback:logback-classic from 1.5.21 to 1.5.22 #​18311
  • Bump com.fasterxml.jackson:jackson-bom from 2.20.0 to 2.20.1 #​18245
  • Bump com.unboundid:unboundid-ldapsdk from 7.0.3 to 7.0.4 #​18262
  • Bump io.micrometer:micrometer-observation from 1.14.12 to 1.14.13 #​18189
  • Bump io.micrometer:micrometer-observation from 1.14.13 to 1.14.14 #​18277
  • Bump io.mockk:mockk from 1.14.6 to 1.14.7 #​18274
  • Bump io.projectreactor:reactor-bom from 2025.0.0 to 2025.0.1 #​18289
  • Bump io.spring.gradle:spring-security-release-plugin from 1.0.10 to 1.0.13 #​18187
  • Bump org-aspectj from 1.9.24 to 1.9.25 #​18186
  • Bump org.apache.kerby:kerb-simplekdc from 2.1.0 to 2.1.1 #​18215
  • Bump org.junit:junit-bom from 6.0.0 to 6.0.1 #​18188
  • Bump org.springframework.data:spring-data-bom from 2025.1.0 to 2025.1.1 #​18312
  • Bump org.springframework:spring-framework-bom from 7.0.0 to 7.0.1 #​18213
  • Bump org.springframework:spring-framework-bom from 7.0.1 to 7.0.2 #​18310
  • Bump tools.jackson:jackson-bom from 3.0.1 to 3.0.2 #​18212
  • Bump tools.jackson:jackson-bom from 3.0.2 to 3.0.3 #​18244

🔩 Build Updates

  • Add Test for ServletRequestPathUtils.parseAndCache(method=null) #​18166
  • Bump antora from 3.2.0-alpha.10 to 3.2.0-alpha.11 in /docs #​18238

❤️ Contributors

Thank you to all the contributors who worked on this release:

@​L33gn21, @​ghusta, @​ronodhirSoumik, @​rwinch, @​sach429, and @​ziqin

v7.0.0

Compare Source

⭐ New Features

  • Add a minimal authorization server configuration #​18153
  • Mark GrantedAuthority#getAuthority as @Nullable #​18014
  • Polish SimpleGrantedAuthority #​18062

🪲 Bug Fixes

  • Correct the org.springframework.security.config.annotation.web.LogoutDsl's property description #​18026
  • Fix webauthn multifactor authentication #​18163

🔨 Dependency Upgrades

  • Bump org.jetbrains.kotlin:kotlin-bom from 2.2.20 to 2.2.21 #​18099
  • Bump org.jetbrains.kotlin:kotlin-gradle-plugin from 2.2.20 to 2.2.21 #​18100
  • Bump tools.jackson:jackson-bom from 3.0.0 to 3.0.1 #​18097
  • Update to Reactor 2025.0.0 #​18173
  • Update to Spring Data 2025.1.0 #​18174
  • Update to Spring Framework 7.0.0 #​18172
  • Update to Spring LDAP 4.0.0 #​18175

❤️ Contributors

Thank you to all the contributors who worked on this release:

@​Kehrlann, @​SimonVonXCVII, @​quaff, and @​therepanic


Configuration

📅 Schedule: Branch creation - "after 10pm every weekday,before 5am every weekday,every weekend" in timezone America/Havana, Automerge - "before 4am on the first day of the month" in timezone America/Havana.

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about these updates again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate bot requested a review from yacosta738 as a code owner December 2, 2025 23:18
@renovate renovate bot requested a review from yacosta738 December 2, 2025 23:18
@coderabbitai
Copy link
Contributor

coderabbitai bot commented Dec 2, 2025

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.


Comment @coderabbitai help to get the list of available commands and usage tips.

@github-actions
Copy link
Contributor

github-actions bot commented Dec 2, 2025

Qodana for JVM

68 new problems were found

Inspection name Severity Problems
Unused symbol 🔶 Warning 42
Invalid YAML configuration 🔶 Warning 5
Unstable API Usage 🔶 Warning 4
Duplicated code fragment ◽️ Notice 9
Unknown HTTP header ◽️ Notice 5
Multi-dollar interpolation can be used in string literals (available since 2.1) ◽️ Notice 1
If-Null return/break/... foldable to '?:' ◽️ Notice 1
Vulnerable declared dependency ◽️ Notice 1

☁️ View the detailed Qodana report

Contact Qodana team

Contact us at [email protected]

@github-actions
Copy link
Contributor

github-actions bot commented Dec 2, 2025

Dependency Review

✅ No vulnerabilities or license issues or OpenSSF Scorecard issues found.

Scanned Files

None

@github-actions
Copy link
Contributor

github-actions bot commented Dec 3, 2025

Test Results

165 tests   159 ✅  25s ⏱️
 38 suites    0 💤
 38 files      6 ❌

For more details on these failures, see this check.

Results for commit 5a176e3.

♻️ This comment has been updated with latest results.

@cloudflare-workers-and-pages
Copy link

cloudflare-workers-and-pages bot commented Dec 3, 2025

Deploying cvix with  Cloudflare Pages  Cloudflare Pages

Latest commit: 5a176e3
Status: ✅  Deploy successful!
Preview URL: https://a0c70f22.cvix.pages.dev
Branch Preview URL: https://renovate-major-spring-securi.cvix.pages.dev

View logs

@cloudflare-workers-and-pages
Copy link

cloudflare-workers-and-pages bot commented Dec 3, 2025

Deploying cvix-app with  Cloudflare Pages  Cloudflare Pages

Latest commit: ed9be62
Status: ✅  Deploy successful!
Preview URL: https://81cba4b0.cvix-app.pages.dev
Branch Preview URL: https://renovate-major-spring-securi.cvix-app.pages.dev

View logs

@renovate renovate bot force-pushed the renovate/major-spring-security branch 17 times, most recently from e6865a2 to d434b5a Compare December 5, 2025 11:24
@github-actions
Copy link
Contributor

github-actions bot commented Dec 5, 2025

Qodana for JVM

79 new problems were found

Inspection name Severity Problems
Unused symbol 🔶 Warning 43
Invalid YAML configuration 🔶 Warning 6
Potentially ambiguous 'kotlin.coroutine.coroutineContext' usage 🔶 Warning 4
Unstable API Usage 🔶 Warning 4
Unresolved reference in KDoc 🔶 Warning 2
Redundant qualifier name 🔶 Warning 2
Unknown HTTP header ◽️ Notice 10
Duplicated code fragment ◽️ Notice 2
Unnecessary type argument ◽️ Notice 2
Multi-dollar interpolation can be used in string literals (available since 2.1) ◽️ Notice 1
String concatenation that can be converted to string template ◽️ Notice 1
If-Null return/break/... foldable to '?:' ◽️ Notice 1
Vulnerable declared dependency ◽️ Notice 1

☁️ View the detailed Qodana report

Contact Qodana team

Contact us at [email protected]

@renovate renovate bot force-pushed the renovate/major-spring-security branch 4 times, most recently from 8b7a673 to 25a12f5 Compare December 5, 2025 20:20
@renovate renovate bot force-pushed the renovate/major-spring-security branch 10 times, most recently from c386440 to 5fd552a Compare December 24, 2025 14:44
@renovate renovate bot changed the title fix(deps): update spring security to v7 (major) chore(deps): update spring security to v7 (major) Dec 24, 2025
@renovate renovate bot force-pushed the renovate/major-spring-security branch 16 times, most recently from 6b8a684 to e03a7e6 Compare December 25, 2025 16:19
@renovate renovate bot force-pushed the renovate/major-spring-security branch from e03a7e6 to 5a176e3 Compare December 25, 2025 16:28
@sonarqubecloud
Copy link

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant